Help w/ Unifi network config and tagged traffic
I'm running Security Spy on a Mac Mini. It has two 10gb ethernets. One (10gb Ethernet) connects to a switch (Unifi 24Pro POE) dedicated to cameras, the other (Sonnet Solo 10G thunderbolt) to the rest of the world. The Sonnet is currently not connected until I figure this out. The purpose of this config is to keep the cameras isolated so that they cannot access the internet and so that their traffic does not interfere w/ the rest of the network.
Cameras all have an assigned IP address of xxx.xxx.27.xxx. Ports on the switch all use a port profile using a Native Network of 'Cams' which is a VLAN of xxx.xxx.27.xxx. Tagged Networks is currently 'Select All'. Am I correct that all traffic from these cameras (which I assume, maybe incorrectly, is untagged) s/b tagged w/ 27?
Am I correct that Tagged Networks should ideally be set to 27 (I need to get around the view-only bug) to insure that no traffic tagged anything but 27 goes through? Or not necessary?
On the Mac Mini. Security Spy can see the cameras if the Ethernet port has a xxx.xxx.1.xxx address and there is a virtual interface with address xxx.xxx.27.xxx. If I change the 27 to anything else it can't see them (so assume they are indeed all tagged 27). If I reassign the virtual interface to the Sonnet then it can't see them (again, they appear to be properly tagged). So far so good.
HOWEVER, if I readdress the ethernet port itself to xxx.xxx.27.xxx (and the virtual interface is 28 or something to avoid conflicts) then it cannot see the cameras.
This is the behavior with the switch port for the mac mini configed as 'all'. However, if I apply the Cams (27) profile then it can no longer see the cameras.
Looking for help both understanding this and configuring it properly.
Thanks,
------- Other info:
UDMP: 1.9.1.3427 Controller v6.1.67
Switch: 4.3.13.11253
MacOS: Big Sur 11.2.3
Port on upstream switch accepts traffic only from from the net mgmt VLAN (xxx.xxx.1.xxx). Native is set to None. I assume this should block any untagged traffic or traffic tagged 27 so should prevent cameras from accessing the internet and calling home to momma unless the cameras are tagging as xxx.xxx.1.xxx?
Cameras all have an assigned IP address of xxx.xxx.27.xxx. Ports on the switch all use a port profile using a Native Network of 'Cams' which is a VLAN of xxx.xxx.27.xxx. Tagged Networks is currently 'Select All'. Am I correct that all traffic from these cameras (which I assume, maybe incorrectly, is untagged) s/b tagged w/ 27?
Am I correct that Tagged Networks should ideally be set to 27 (I need to get around the view-only bug) to insure that no traffic tagged anything but 27 goes through? Or not necessary?
On the Mac Mini. Security Spy can see the cameras if the Ethernet port has a xxx.xxx.1.xxx address and there is a virtual interface with address xxx.xxx.27.xxx. If I change the 27 to anything else it can't see them (so assume they are indeed all tagged 27). If I reassign the virtual interface to the Sonnet then it can't see them (again, they appear to be properly tagged). So far so good.
HOWEVER, if I readdress the ethernet port itself to xxx.xxx.27.xxx (and the virtual interface is 28 or something to avoid conflicts) then it cannot see the cameras.
This is the behavior with the switch port for the mac mini configed as 'all'. However, if I apply the Cams (27) profile then it can no longer see the cameras.
Looking for help both understanding this and configuring it properly.
Thanks,
------- Other info:
UDMP: 1.9.1.3427 Controller v6.1.67
Switch: 4.3.13.11253
MacOS: Big Sur 11.2.3
Port on upstream switch accepts traffic only from from the net mgmt VLAN (xxx.xxx.1.xxx). Native is set to None. I assume this should block any untagged traffic or traffic tagged 27 so should prevent cameras from accessing the internet and calling home to momma unless the cameras are tagging as xxx.xxx.1.xxx?